Historical systems and recovery evidence
Historical pages preserve reconstruction details and failure lessons. They are not current procedures.
Platform transitions
| Historical system | Replacement | Evidence period |
|---|---|---|
pfSense VM 110, old 192.168.100.0/24 LAN |
OPNsense VM 100, LAN 192.168.0.0/24 |
June–July 2026 |
Docker CT 100 and /root/<project> |
Rootless Podman CT 101 and /opt/podman |
June 2026 |
| Traefik ingress | Caddy CT 103 |
June 2026 |
Pi-hole and Cloudflared CT 107 |
Technitium CT 102 |
June–July 2026 |
| Drone direct deployment | Forgejo Actions shared publish volume | July 2026 |
Nginx/direct CT 103 docs |
CT 101 docs-static behind CT 103 |
July 2026 |
| Proxmox as subnet router | Dedicated CT 105 |
July 2026 |
Retained material
- pfSense historical reference
- Docker runtime snapshot
- Caddy and Technitium migration record
- Pre-reinstall checklist
- Recovery assessment
- Recovery assumptions
- Docker recovery script usage
- Historical restoration runbook
- Historical restoration validation
- June 2026 refactor report
The repository scripts in scripts/backup/, scripts/restore/, and the
Docker creation/recovery scripts are historical until updated and tested
against the current inventory. They must not be executed as current production
procedures merely because they remain executable.
Neutral findings retained
- The old internal
.100subnet conflicted with Starlink management space. - Rootless Podman inside an unprivileged LXC requires subordinate IDs within the guest-visible range and a narrow TUN passthrough.
- Technitium can be active while listening only on loopback; listener health must test the service address.
- A Forgejo Actions job can appear successful while a rejected bind mount leaves output ephemeral.
- A healthy Caddy route can serve stale content when publication stopped.
- Unbound was rejected for the Proxmox bootstrap resolver after AppArmor denied required socket creation; host-local dnsmasq is the selected design.